소개
Empowers security operations by providing expert guidance on creating sophisticated stateful rules within the LimaCharlie ecosystem. It helps users move beyond simple, isolated detections to identify complex attack patterns—such as multi-stage exploits, brute force attempts, and malicious process trees—by maintaining historical context and relational data across multiple events. The skill ensures high-performance detection by emphasizing early filtering and optimal use of stateful operators like with_child and with_descendant.